feat(email-writing): add hardened contextual-orchestrator boundary - #1356
feat(email-writing): add hardened contextual-orchestrator boundary#1356seonghobae wants to merge 46 commits into
Conversation
|
Warning Review limit reached
Next review available in: 13 minutes Limit details: You’ve used all 1 included review currently available under your plan. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (18)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
…ask4' into feat/llm-email-writing-orchestrator-task5
|
PR governance metadata gate is not ready for
|
|
Bugbot is not enabled for your account, so this pull request was not reviewed. Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs. |
…ask4' into feat/llm-email-writing-orchestrator-task5 Retarget Task 5 onto live #1329 head 4570747 (merged onto live #1328 51fb5e8 / #1327 fb7c406 / #1322 bfc2df1 / develop@dd8d1519). Preserve the hardened contextual-orchestrator boundary. Do not restore write-capable Task 5 promotion/finalize workflows. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
|
@coderabbitai review Please review the unchanged exact current head |
|
|
Bring feat/llm-email-writing-candidate-task6 onto the current feat/llm-email-writing-orchestrator-task5 head without changing Task 6 candidate-parse semantics or restoring write-capable workflows. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Stack dependency
This Draft PR is stacked on #1329 (
feat/llm-email-writing-context-task4) and implements Task 5 only from the committed LLM email-writing implementation plan.Customer next action
This PR is orchestrator-boundary only. Customers should continue to write and send email with the current editor and send path. No writing-guidance feature, language profile, or model is available in product. Writing and sending stay on the current path.
Included
contextual-orchestratortransport forrouteandconductmodes;compileall.Security and privacy boundary
The browser cannot supply an orchestrator endpoint, credential, model profile, provider route, or orchestration evidence. The server resolves one owner-scoped configuration and rejects incomplete or unsafe settings before dispatch. Upstream payloads are untrusted data, not instructions. Public errors contain stable codes only.
The transport sends only the fixed
/v1/chat/completionspath, does not follow redirects, does not trust ambient proxy settings, and does not persist upstream response metadata.Workflow-authority correction — 2026-08-17
The three historical write-capable workflow identities remain absent and were not restored by this retarget:
.github/workflows/email-writing-orchestrator-promotion.yml;.github/workflows/email-writing-orchestrator-promotion-v2.yml;.github/workflows/email-writing-task5-finalize.yml.The remaining PR-local workflow files are read-only test workflows (
permissions: contents: read) withpersist-credentials: false. No Task 5 PR-local workflow in the current diff is authorized to create/close/merge PRs, enable auto-merge, mutate source, or push commits.Exact-head retarget onto live #1329
Previous head (exact current PR head at launch):
GitHub last showed base
feat/llm-email-writing-context-task4at stale:Current head (normal merge commit, not squash, not rebase, not force-push):
Live parent #1329 (
feat/llm-email-writing-context-task4) merged as the second parent:Normal merge commit parents:
0c0ac2b598a8338a257e69bcca4d00b6fe20daf54570747ccebd57ccaab30ffc68239f0c9d2f1ca0Live parent #1329 already contains #1328
51fb5e8543247b1e5c790f3fdf98424c8fbed669/ #1327fb7c406ee1328a6ac42dbaf54bb6852c199d8b0a/ #1322bfc2df112136bb9fe358778d701e78bf9e78b685/ develop@dd8d15191338b841f9e6f3a06507c6a5643b95d0.ADR numbering follows the live parent:
0004-status-weighted-calendar-conflicts.md);backend/main.pyto keep both the calendar-conflicts and orchestrator-config routers.Alembic head after merge:
Parent still carries
20260812_email_writing_evidenceon0017_merge_newsdom_carddav_heads. This slice's revision did not collide and remains20260813_email_orchestratorwithdown_revision = 20260812_email_writing_evidence.Local validation counts on
9cd9b953a2dd236aebe1fcdc25e59ba3e9388505:tests/test_contextual_orchestrator_client.py)tests/test_contextual_orchestrator_hardening.py)tests/test_email_writing_orchestrator_module_boundary.py)tests/test_email_writing_orchestrator_scope.py)tests/test_email_writing_orchestrator_migration.py)tests/test_email_writing_orchestrator_config_api.py)tests/test_email_writing_orchestrator_terminal_coverage.py)522statements,148branches,fail-under=100)compileallfor Task 5 sources: okgit diff --check: okTimeout/Fatal/Warn/DeniedPredecessor evidence does not transfer. Checks, reviews, and security evidence recorded for
0c0ac2b5,0376d0ac, or any earlier head are non-passing for this head.Merge boundary
Keep this PR Draft while #1329 and its parent stack remain unmerged. This slice does not add candidate-review prompts, fast-mlsirm Judge calls, admission policy, review APIs, editor UI, send/publish behavior, scheduled model calls, or a release. Merge only after the unchanged exact head and its then-live base satisfy every applicable repository/inherited ruleset, all required CI/security/coverage/dependency/package/provenance workflows are terminal-success, every addressed thread is resolved, and a qualifying independent non-author post-last-push approval exists. Queued, pending, skipped-required, neutral, failed, absent, stale, predecessor-head, model-only, status-only, author-only, or cancelled evidence is non-passing. This update does not approve, merge, squash, empty-requeue, force-cancel, or mark Ready.